Technical Tip: How to setup a wireless network on FortiGate using Tunnel-Mode SSID
| Description | This article describes how to create a wireless-only dedicated network called Tunnel Mode. The client traffic is tunneled back to the FortiGate over CAPWAP and managed centrally. |
| Scope | FortiGate v7.4.8, v7.6.x |
| Solution |
Note: Starting FortiOS v7.6.5, the quarantine option is disabled by default when creating tunnel-mode SSID, preventing automatic creation of unused quarantine VLANs and simplifying configuration and management.
In the CLI:
Endeavour-kvm63 # config wireless-controller vap Endeavour-kvm63 (vap) # edit tunnel_vap Endeavour-kvm63 (tunnel_vap) # sh fu | grep quarantine Endeavour-kvm63 (tunnel_vap) # |






